GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE
- ID
- 14793
- Status
- new
- Published
- 14 Aug 2026, 2:45 AM
- Fetched
- 17 Aug 2026, 8:47 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/unpatched-geoserver-zero-day-targeted.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Excerpt
A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that can lead to remote code execution (RCE). The security defect remains unpatched. It was first disclosed on August 12, 2026, at 10:46 UTC, by a researcher named @
Summary
No summary yet. It will appear after the daemon summarizes this item.